- linux-py:
sudo apt install python3 - win-py:
https://www.python.org/downloads/
- No nonsense.
root:~# webkit -h
usage: webkit.py [-h] [-s SUBDOMAIN] [-q SQL] [-x XSS] [-c CLICKJACKING] [-i INFO]
options:
-h, --help show this help message and exit
-s SUBDOMAIN, --subdomain SUBDOMAIN
-q SQL, --sql SQL
-x XSS, --xss XSS
-c CLICKJACKING, --clickjacking CLICKJACKING
-i INFO, --info INFOroot:~# webkit -s domain.com
==========================================
[+] http://domain.com/login
[+] http://domain.com/sms
[+] http://domain.com/ipv4
[+] http://domain.com/logout
[-] http://domain.com/admin
==========================================
root:~# webkit -q http://domain.com/
[*] Trying https://domain.com/"
[*] Trying https://domain.com/'
[+] Detected 0 forms on https://domain.com/.
root:~# webkit -x https://domain.com
[+] Detected 1 forms on https://domain.com.
[+] Submitting malicious payload to https://domain.com/search
[+] Data: {'CENSURED': 'CENSURED', 'CENSURED': 'CENSURED', 'CENSURED': 'CENSURED', 'CENSURED': 'CENSURED', 'CENSURED': 'CENSURED', 'CENSURED': 'CENSURED', 'CENSURED': 'CENSURED'}
root:~# webkit -c domain.com
[-] roblox.com is not vulnerable to clickjacking.
[*] Response Headers:
| BLABLALBA
| BLABLALBA
| BLABLALBA
| BLABLALBA
| BLABLALBA
| BLABLALBA
root:~# webkit -i domain.com
The IP <domain.com> is : [127.0.0.1]
WEB KIT V.1.0
=====================================================
IP : 127.0.0.1
STATUS : success
COUNTRY : LOL
COUNTRY CODE : LOL
REGION : L
CITY : LOL
ZIP : LOL
LAT : 50.###
LON : 8.####
TIMEZONE : Hide
ISP NAME : Domain TEST
=====================================================
v1.0 ⋮ 29/06/2024+ WEBKIT Information
Subdomain
Sql Injection Scanner
XSS vulnerability scanner
Clickjacking
Get information about a site